SUSE
First CVE: May 13, 2019Active for: 7 years
244
CVEs Published
More CVEs Published than 81% of tracked CNAs
30.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by SUSE as a CNA, 50.0% affect products that SUSE develops as a vendor.
50.0%
50.0%
Self-reported: 122Third-party: 122
Of all the CVEs published that affect products developed by SUSE, 10.0% are self-published by SUSE as a CNA.
90.0%
Self-published: 122Published by other CNAs: 1,103
Trends Over Time
The number and severity of CVEs published by SUSE over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 13, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by SUSE as a CNA, regardless of affected vendor or product.
244 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46811CRITICAL A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. | Jul 30, 2025 | 9.8 | 53 | NO | YES |
CVE-2026-44935CRITICAL Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be us | Jul 2, 2026 | 9.9 | 43 | NO | NO |
CVE-2026-56004CRITICAL A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as | Jul 2, 2026 | 10.0 | 43 | NO | NO |
CVE-2021-36782CRITICAL A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to us | Sep 7, 2022 | 9.9 | 43 | NO | YES |
CVE-2026-44941HIGH A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overw | Jul 2, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-56003HIGH A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56001HIGH A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code withi | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56002HIGH A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server. | Jul 8, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-41052HIGH Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12. | Jun 29, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-41050CRITICAL Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets fro | May 13, 2026 | 9.9 | 39 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA244 CVEs
33%
50%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local113 (46.3%)
Network124 (50.8%)
Unknown0 (0.0%)
Physical1 (0.4%)
Adjacent Network5 (2.0%)
Attack Complexity
Low221 (90.6%)
High23 (9.4%)
Unknown0 (0.0%)
User Interaction
None196 (80.3%)
Unknown0 (0.0%)
Required42 (17.2%)
Privileges Required
Low147 (60.2%)
High21 (8.6%)
None76 (31.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (244 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.8% of CVEs· 86th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.4% of CVEs· 76th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by SUSE as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SUSE as a CNA — matched by CVE ID, not by organization name.